Sanitize filenames before using in Content-Disposition header

This commit is contained in:
Marc Delisle
2011-08-08 17:28:54 -04:00
committed by Herman van Rink
parent e11e55cb06
commit ae20845e36

View File

@@ -70,7 +70,7 @@ if (isset($ct) && !empty($ct)) {
header($content_type);
if (isset($cn) && !empty($cn)) {
header('Content-Disposition: attachment; filename=' . $cn);
header('Content-Disposition: attachment; filename=' . PMA_sanitize_filename($cn));
}
if (!isset($resize)) {